LibraryData and agents2020Design paperCorpus record
CCIP Read—Secure offchain data retrieval
ERC 3668. Nick Johnson.
ERC 3668, CCIP Read—Secure offchain data retrieval. Contracts wishing to support lookup of data from external sources may, instead of returning the data directly, revert using OffchainLookup(address sender, string[] urls, bytes callData, bytes4 callbackFunction, bytes extraData).
Status in the source: Final. A reading of the public specification, not a copy of it and not a certification.
CCIP Read—Secure offchain data retrieval is worth reading for the rule it actually adds: Contracts wishing to support lookup of data from external sources may, instead of returning the data directly, revert using OffchainLookup(address sender, string[] urls, bytes callData, bytes4 callbackFunction, bytes extraData).
The five-minute read
The rule
Contracts wishing to support lookup of data from external sources may, instead of returning the data directly, revert using OffchainLookup(address sender, string[] urls, bytes callData, bytes4 callbackFunction, bytes extraData).
What was already failing
An interface that is only a name in a repository will be re-implemented differently by every team, which is how shared contracts break.
What the number does not mean
The source marks this final. That is a statement about the text, not a promise that every wallet or node has shipped it.
What a builder should be able to point at
An implementation either constrains RPC, URL, CCIP or it is a different design.
One action, walked through
- Open ERC 3668 and read the status line before the examples.
- Write down the rule in one sentence. A fair version of that sentence is: Contracts wishing to support lookup of data from external sources may, instead of returning the data directly, revert using OffchainLookup(address sender, string[] urls, bytes callData, bytes4 callbackFunction, bytes extraData).
- Name the object that changes: RPC, URL, CCIP.
- Ask what an old client, an old contract, or an offline counterparty does. If the document is silent, the silence is part of the design.
The argument, unpacked
What the text is allowed to settle
Ethereum Request for Comment 3668 can settle the shape of CCIP Read—Secure offchain data retrieval. It cannot settle whether a later client, a later fork, or a later wallet still does this.
What this page will not pretend
There is no benchmark, no adoption number, and no claim that the mechanism is safe outside the assumptions written in the source.
What has to be true
- You are implementing ERC 3668 at the status the text itself states: Final.
- The object that has to change is RPC, URL, CCIP. A neighbouring document with a similar name is not this one.
- Status in the header is not adoption.
What happened after the paper
The source marks this final. That is a statement about the text, not a promise that every wallet or node has shipped it. Later documents can narrow, replace, or ignore this one. Cite the number you mean.
What to check before you use the idea
- What must an implementation of CCIP Read—Secure offchain data retrieval accept, and what may it ignore?
- Is this consensus, peer policy, or an application interface?
- Which names does the text pin down: RPC, URL, CCIP?
Terms
- ERC 3668
- The public text titled CCIP Read—Secure offchain data retrieval.
- Final
- The document's own label for how finished the text is. It is not a market fact.
The problem the paper names
An interface that is only a name in a repository will be re-implemented differently by every team, which is how shared contracts break.
What the design proposes
- Contracts wishing to support lookup of data from external sources may, instead of returning the data directly, revert using OffchainLookup(address sender, string[] urls, bytes callData, bytes4 callbackFunction, bytes extraData).
- Clients supporting this specification then make an RPC call to a URL from urls, supplying callData, and getting back an opaque byte string response.
- Finally, clients call the function specified by callbackFunction on the contract, providing response and extraData.
How the mechanism is specified
- Taken from the specification, the next constraint is: Clients supporting this specification then make an RPC call to a URL from urls, supplying callData, and getting back an opaque byte string response.
- Locate RPC, URL, CCIP in ERC 3668 and apply it to one transaction or call.
- Then check the failure the class of rule always has: a node that did not upgrade, a reverted call, a replayed signature, or a peer that does not speak the message.
What this page does not treat as proven
- This document does not set a fee, a valuation, or a security proof.
- Status in the header is not adoption.
- The source marks this final. That is a statement about the text, not a promise that every wallet or node has shipped it.
Why a venture studio still reads it
Use ERC 3668 when a pitch says 'CCIP Read—Secure offchain data retrieval' without saying whether the rule is consensus, policy, or an interface. The number is the citation. The pitch is not.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
